OmList is a product of Omlist LLC (“Omlist,” “we,” “our,” or “us”). This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use:
- the OmList platform at omlist.com (no mobile app at this time),
and all associated services, dashboards, and tools.
We are committed to being transparent about our data practices. This policy is written in plain language so you can understand what we do with your information.
1. Who We Are
| Legal Entity | Omlist LLC |
|---|---|
| Formed In | Texas (registered in California) |
| Mailing Address | 2443 Fillmore St #288, San Francisco, CA 94115 |
| Website | https://omlist.com |
| Parent Company | https://www.omlist.com |
| Privacy Contact | privacy@omlist.com |
2. Scope of This Policy
This policy applies to personal information we process when you:
- Register for an account and create a profile;
- Swipe, rate, or build a Rec List of movies or other entertainment titles;
- Use Battle Mode or other recommendation features;
- Use AI-powered or algorithmic features (e.g., taste-matching and recommendation scoring);
- Submit support requests, feedback, or bug reports;
- Opt in to optional OmList product or marketing emails;
- Visit our website and interact with our platform.
This policy does not apply to third-party websites or other services that you access through links on our Service. Those providers have their own privacy policies, and we encourage you to review them.
3. Information We Collect
3.1 Information You Provide Directly
Account and Profile Information:
- Name
- Email address
- Phone number (if provided)
- Profile photo (if provided via Google OAuth)
- Viewing/streaming preferences, favorite genres, and platform subscriptions you tell us about
Entertainment Preference Data:
- Titles you swipe on, like, dislike, or add to a Rec List
- Battle Mode selections and results
- Ratings and reviews you submit
Communications:
- Support requests and messages
- Feedback, bug reports, and feature suggestions
- Survey responses
- Newsletter sign-ups and email preferences
3.2 Information Collected Automatically
Usage Data:
- Pages and features accessed; titles viewed, swiped, and added to Rec Lists
- Search queries and filter/preference selections
- Feature interaction patterns
- Battle Mode session telemetry
Device and Network Data:
- IP address
- Browser type and version
- Device type and operating system
- Referring URL
- Approximate location inferred from IP address
Cookies and Similar Technologies:
- Authentication and session cookies
- Browser local storage for your preferences and Rec List
- Cookieless analytics (see Section 7)
3.3 Information from Third-Party Services
Google OAuth: When you sign in with Google (via Supabase Auth), we receive your name, email address, and profile photo from Google. We do not receive your Google password.
Payments: OmList does not currently process payments or offer paid plans. If billing is introduced in the future, this section will be updated to describe how payment information is collected and processed before that feature goes live.
3.4 Sensitive Personal Information
OmList’s features are not designed to collect sensitive personal information, and we do not ask for it. If you voluntarily include sensitive personal information in a review, rating, or support request, we process it only to provide the Service you requested and do not use it to infer characteristics about you, target advertising, or for any purpose other than providing and securing the Service. You may delete this information at any time by editing your profile, deleting the content, or deleting your account.
4. How We Use Your Information
We use your personal information for the following purposes:
| Purpose | Examples |
|---|---|
| Providing the Service | Account creation, profile management, swiping, Rec List building, Battle Mode |
| AI and Algorithmic Processing | Taste-matching and personalized recommendation scoring based on your swipes, ratings, and Rec List |
| Communications | Responding to support requests, sending transactional emails (account confirmations, service announcements) |
| Optional Marketing Email | If you opt in, we use your email to send occasional product announcements, tips, and OmList updates |
| Product Improvement | Analyzing usage patterns to improve features, fix bugs, and develop new functionality (using aggregated or de-identified data where possible) |
| Safety and Security | Detecting abuse, unauthorized access, fraud, and policy violations; protecting the integrity of the Service |
| Legal Compliance | Complying with applicable laws, regulations, court orders, and legal processes; enforcing our Terms of Service |
4.1 AI and Automated Processing
OmList uses algorithmic and AI-assisted tools to assist with:
- Taste-matching: Comparing your swipes, ratings, and Rec List against catalog data and (in aggregate) other users’ activity to generate recommendations
- Recommendation scoring: Ranking and surfacing titles we predict you’re likely to enjoy
Important disclosures about our AI and algorithmic processing:
- Recommendations are assistive — you choose what to watch, rate, swipe on, or add to your Rec List. Nothing is submitted or acted on without you.
- We use AI infrastructure providers to process data supporting these features (see Section 5). These providers act on our behalf and are contractually restricted from using your data to train their general-purpose models.
- We do not use your personal Content (profile data, ratings, Rec List) to train public AI models in a way that identifies you. We may use aggregated, de-identified data and patterns to improve our own recommendation features.
- Recommendations may be imperfect or reflect incomplete catalog data. We do not guarantee accuracy or relevance.
5. How We Share Your Information
We do not sell your personal information. We share information only in the following circumstances:
5.1 Service Providers and Processors
We use trusted third-party service providers who process data on our behalf:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database hosting, authentication (Google OAuth), file storage | Account data, profile data, usage data, entertainment preference data |
| Vercel | Web application hosting, edge functions, cron infrastructure | Request logs, application data in transit |
| AI/LLM Providers (e.g., Anthropic, OpenAI, Google, via direct integration or routing services such as OpenRouter) | Taste-matching, recommendation scoring, content classification | Ratings and preference data, catalog metadata, prompts (sent for processing; providers contractually restricted from using data for general-model training) |
| Resend | Transactional and newsletter email delivery | Email address, message content |
| Cloudflare | CDN, security | Request metadata |
| OAuth sign-in | Authentication tokens (we receive name, email, photo) | |
| Analytics providers | Usage analytics and performance monitoring | Anonymized/aggregated usage data |
We require our service providers to protect your data and use it only for the purposes we specify. A current sub-processor list is available on request from privacy@omlist.com.
5.2 Aggregated, De-Identified Insights
Because our recommendation feature works by comparing your list of titles against other users’ lists, we also compile aggregated, de-identified statistics about how our user base engages with the platform as a whole (for example, how many users rank a given title as their #1). We may use and share these aggregated insights, including for marketing purposes. This aggregated data does not identify you personally and is not shared, sold, or used in a way that discloses your individual personal information.
5.3 Internal Access by Authorized Personnel
A small number of authorized Omlist personnel (including the founders and any contracted support staff who have signed appropriate confidentiality and data-handling agreements) may access account, profile, or usage data on a need-to-know basis to: (a) operate and curate the Service, (b) respond to support requests, (c) investigate abuse or security incidents, and (d) review content quality.
5.4 Legal Compliance and Protection
We may disclose information when we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, court order, or legal process;
- Protect the rights, safety, or property of Omlist, our users, or the public;
- Detect, prevent, or address fraud, security, or technical issues;
- Enforce our Terms of Service.
5.5 Business Transfers
In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such transfer and any choices you may have regarding your information.
5.6 With Your Direction or Consent
We may share information where you explicitly request or authorize it.
6. Data Retention
We retain your personal information only as long as reasonably necessary for the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Account and profile data | For the duration of your account, plus up to 30 days after account deletion to process the request |
| Entertainment preference data (swipes, ratings, Rec List, Battle Mode history) | For the duration of your account; deleted upon account deletion or upon your request |
| Usage and analytics data | Up to 24 months, then aggregated or deleted |
| Support communications | Up to 24 months after resolution |
| Server logs | Up to 90 days |
When data is no longer required, we delete, de-identify, or anonymize it. You may request deletion of your data at any time (see Section 8).
7. Cookies and Tracking Technologies
7.1 What We Use
| Type | What it is | Duration |
|---|---|---|
| Essential/Authentication cookies | Maintaining your login session, security, CSRF protection | Session or short-lived |
| Browser local storage | Remembering your settings, preferences, and Rec List. Stored on your device by your browser; not transmitted to us as a cookie. | Until you clear it |
| Analytics | Cookieless usage analytics measuring page views and feature usage. Sets no cookie and stores no persistent identifier on your device. | No device storage |
7.2 What We Don’t Use
We do not currently use advertising cookies, SDKs, or device advertising identifiers (such as IDFA/AAID), and we are not currently an advertising platform. If we introduce advertising, such as an in-app banner ad product, in the future, we will update this policy accordingly before doing so. We also do not use:
- Cross-site tracking pixels for ad targeting
- Fingerprinting technologies
- Google Analytics, advertising pixels, or any ad network
7.3 Your Cookie Choices
Because the only cookies we set are strictly necessary ones that keep you logged in, we do not show a cookie consent banner — there is no non-essential cookie for you to accept or decline.
You can still control cookies through your browser settings. Most browsers allow you to:
- Block all cookies
- Block only third-party cookies
- Delete cookies when you close your browser
- Be notified when a cookie is set
Disabling essential cookies may prevent you from using certain features of the Service (such as staying logged in). Clearing your browser’s local storage will reset your saved preferences and Rec List.
7.4 Global Privacy Control (GPC)
We do not sell or share personal information for cross-context behavioral advertising, so there is nothing for a GPC signal to opt you out of — the outcome a GPC signal is designed to produce is already our default for every user, whether or not your browser sends one.
If our practices ever change such that a sale or share does occur, we will treat a GPC signal as a valid opt-out request as required by California law, and will provide the opt-out mechanism described in Section 9.
8. Your Privacy Rights
8.1 Rights for All Users
Regardless of where you live, you can:
- Access your personal information by viewing your profile and account settings;
- Update or correct your information through your account settings;
- Delete your account and associated data yourself from Profile → Delete Account, or by contacting support@omlist.com;
- Download your data yourself from Profile → Export Your Data. No request to us is required;
- Withdraw consent for optional processing activities, such as marketing communications.
8.2 California Residents — CCPA/CPRA Rights
If you are a California resident, you have the following rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
Right to Know / Access: You can request the categories and specific pieces of personal information we have collected, used, disclosed, or sold/shared about you.
Right to Delete: You can request that we delete your personal information, subject to certain legal exceptions.
Right to Correct: You can request correction of inaccurate personal information.
Right to Opt Out of Sale/Sharing: You have the right to opt out of the sale or sharing of your personal information. Omlist does not sell personal information for monetary consideration. The aggregated, de-identified statistics described in Section 5.2 do not identify you personally and are not “personal information” for purposes of this right. If any of our other analytics practices are later deemed “sharing” under California law, we will provide the required opt-out mechanism.
Right to Limit Use of Sensitive Personal Information: As described in Section 3.4, we do not collect sensitive personal information by design. You may still delete any voluntarily provided information at any time.
Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights. You will not receive a different level of service for exercising your rights.
8.3 EEA, UK, and Swiss Residents — GDPR / UK GDPR Rights
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the EU General Data Protection Regulation (GDPR), the UK GDPR, and/or the Swiss Federal Act on Data Protection, including:
- Access, rectification, erasure, and portability of your personal data;
- Restriction of, and objection to, processing in certain circumstances;
- Withdrawal of consent at any time, where processing is based on consent;
- The right to lodge a complaint with your local data protection authority (e.g., your national DPA in the EEA, the UK ICO, or the FDPIC in Switzerland).
Legal bases for processing. We rely on the following GDPR legal bases:
- Contract performance (Art. 6(1)(b)): to provide the Service you signed up for, including recommendation features tied to your account;
- Legitimate interests (Art. 6(1)(f)): to operate, secure, and improve the Service and prevent abuse (where these interests are not overridden by your rights);
- Consent (Art. 6(1)(a)): for optional processing such as marketing emails or non-essential analytics;
- Legal obligation (Art. 6(1)(c)): to comply with tax, accounting, or other legal requirements.
International transfers. We are a U.S. company. When we transfer personal data from the EEA, UK, or Switzerland to the United States or other third countries, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable). You may request a copy of these safeguards from privacy@omlist.com.
If you are an EEA/UK/Swiss user and would like to designate an EU/UK representative contact (or have questions about cross-border transfers), email privacy@omlist.com.
8.4 How to Exercise Your Rights
Submit requests via:
- Email: privacy@omlist.com
- Mail: Omlist LLC, 2443 Fillmore St #288, San Francisco, CA 94115
Verification: We may need to verify your identity before fulfilling your request. We will typically verify by confirming information associated with your account (such as your email address). If we cannot verify your identity, we may deny the request and explain why.
Authorized Agents: You may designate an authorized agent to submit requests on your behalf. The agent must provide written authorization signed by you, and we may still ask you to verify your identity directly.
Response Timeline: We will respond to verifiable requests within 45 days (CCPA) or 30 days (GDPR/UK GDPR). If we need additional time, we will notify you and may take up to 90 days total.
9. Do Not Sell or Share My Personal Information
Omlist does not sell your personal information for monetary consideration. We do not share your personal information for cross-context behavioral advertising purposes. The aggregated, de-identified statistics described in Section 5.2 do not identify you personally and are not “personal information” for purposes of this section.
If you are a California resident and wish to exercise your right to opt out, or if you have questions about how we handle your data, contact us at privacy@omlist.com.
Because we neither sell nor share personal information, there is no sale or share for you to opt out of — the protection is already applied to every user by default. See Section 7.4 for how this interacts with Global Privacy Control (GPC) signals.
10. Email Communications
We send two categories of email:
- Transactional / service email — required for the Service: account confirmations, password resets, security alerts, and important policy updates. You cannot fully opt out of these while you have an active account, but you can close your account.
- Marketing email — optional: occasional product announcements, tips, and OmList updates. These are sent only to users who opt in (or, where permitted, on an opt-out basis consistent with CAN-SPAM and applicable law). Every marketing message contains an unsubscribe link, and you can also unsubscribe at any time by emailing privacy@omlist.com.
We do not sell, rent, or share your email address with any third party — including affiliated companies, partner publications, or other LLCs in the Omlist family. OmList accounts are separate from any other newsletter or service you may subscribe to elsewhere.
11. Children’s Privacy
OmList is intended for users who are at least 18 years old (or the age of majority in their jurisdiction). We do not knowingly collect personal information from anyone under 16 years of age. If we learn that we have collected personal information from a child under 16, we will take steps to delete that information as soon as possible. If you believe we have inadvertently collected information from a child, please contact us at privacy@omlist.com.
12. Data Security
We implement administrative, technical, and organizational safeguards designed to protect your personal information, including:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL.
- Encryption at rest: Sensitive data is encrypted at rest in our databases.
- Access controls: Access to personal information is restricted to authorized personnel on a need-to-know basis.
- Authentication: We use industry-standard authentication mechanisms (Google OAuth via Supabase Auth) and do not store plaintext passwords.
- Vendor security: We evaluate the security practices of our third-party service providers and require appropriate safeguards.
- Monitoring: We monitor for unauthorized access, security incidents, and suspicious activity.
No system is perfectly secure. While we take reasonable measures to protect your information, we cannot guarantee absolute security. You are responsible for keeping your account credentials secure and notifying us promptly if you suspect unauthorized access.
12.1 Data Breach Notification
If we discover a security breach affecting your personal information, we will notify affected users and applicable regulators as required by law — including, where applicable, GDPR/UK GDPR’s 72-hour notification window and any state breach-notification statutes. Notice will describe the nature of the breach, the categories of data involved, and steps we are taking, to the extent we are able to share that information at the time of notice.
13. International Users
OmList is operated from the United States. If you access the Service from outside the United States, your personal information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your home country. For EEA, UK, and Swiss users, the safeguards described in Section 8.3 apply.
By using the Service, you consent to the transfer of your information to the United States as described in this policy. We take steps to ensure your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.
14. Third-Party Services
Our Service may link to or interact with third-party websites and streaming platforms referenced in our catalog. These third parties have their own privacy policies and practices, which we do not control and are not responsible for.
We encourage you to review the privacy policies of any third-party service before providing your personal information.
Key third-party services integrated with OmList:
- Google (privacy policy) — OAuth sign-in
- Supabase (privacy policy) — Infrastructure and authentication
- Vercel (privacy policy) — Web hosting
- Resend (privacy policy) — Email delivery
- Cloudflare (privacy policy) — CDN and security
- Anthropic / OpenAI / Google AI — LLM providers (data sent for processing under contracts restricting general-model training)
15. CCPA Category Disclosure
In the preceding 12 months, we have collected and may have disclosed for business purposes the following categories of personal information (as defined by the CCPA):
| CCPA Category | Collected | Disclosed to Service Providers | Sold/Shared |
|---|---|---|---|
| Identifiers (name, email, IP address, account ID) | ✅ | ✅ | ❌ |
| Customer records (name, phone) | ✅ | ✅ | ❌ |
| Commercial information (entertainment preferences, Rec List, Battle Mode activity) | ✅ | ✅ | ❌ |
| Internet/network activity (browsing, search, interactions) | ✅ | ✅ | ❌ |
| Geolocation data (approximate, from IP) | ✅ | ✅ | ❌ |
| Inferences (taste-match scores, recommendations) | ✅ | ✅ | ❌ |
| Sensitive personal information (only what users voluntarily provide) | Rarely | ✅ (limited) | ❌ |
Sources: Directly from users, automatically via the Service, and from third-party authentication providers (Google OAuth).
Business purposes: Providing and improving the Service, AI-assisted recommendation and taste-matching, security, legal compliance.
We do not sell or share personal information for cross-context behavioral advertising. Aggregated, de-identified usage statistics may be used or shared for marketing purposes; these do not identify any individual and are not “personal information” for CCPA purposes.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations.
- Material changes: We will provide notice via email and/or a prominent notice on the Service at least 30 days before material changes take effect.
- Minor changes: Non-material changes (such as formatting or clarifications) may be made without prior notice.
The “Last Updated” date at the top of this page indicates when the most recent changes were made.
Your continued use of the Service after the effective date of an updated policy constitutes your acceptance of the changes.
17. Contact Us
For privacy questions, data requests, or concerns:
Omlist LLC 2443 Fillmore St #288, San Francisco, CA 94115
Privacy inquiries: privacy@omlist.com General support: support@omlist.com Legal inquiries: legal@omlist.com Website: https://omlist.com Parent company: https://www.omlist.com
We aim to respond to privacy inquiries within 10 business days and to formal CCPA requests within 45 days (extendable to 90 days with notice), or 30 days for GDPR/UK GDPR requests (extendable to 90 days with notice).